PatchSiren cyber security CVE debrief
CVE-2022-48935 Siemens CVE debrief
A vulnerability in the Linux kernel's netfilter nf_tables subsystem could allow improper handling of flowtable hooks during network namespace exit. The issue stems from missing unregistration of flowtable hooks when a network namespace exits, potentially leading to use-after-free conditions. Siemens has assessed this vulnerability as affecting certain industrial networking products running SINEC OS, including the RUGGEDCOM RST2428P and SCALANCE X-family switches. The vulnerability was resolved in the Linux kernel by ensuring proper cleanup of flowtable hooks during netns teardown. Organizations should apply vendor-provided updates and follow defense-in-depth practices for industrial control systems.
- Vendor
- Siemens
- Product
- RUGGEDCOM RST2428P (6GK6242-6PA00)
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2026-02-25
- Advisory published
- 2025-08-12
- Advisory updated
- 2026-02-25
Who should care
Organizations operating Siemens industrial networking infrastructure including SCALANCE X-family switches and RUGGEDCOM devices, particularly those in critical infrastructure sectors. Security teams responsible for OT/ICS environments should prioritize this for patch management cycles.
Technical summary
The vulnerability exists in the Linux kernel's netfilter nf_tables subsystem where flowtable hooks were not properly unregistered when a network namespace exits. This can lead to use-after-free conditions as hooks may continue to reference freed memory. The fix ensures proper cleanup by unregistering flowtable hooks during netns exit. Affected Siemens products utilize SINEC OS, which incorporates the vulnerable Linux kernel components. The CISA advisory indicates the vulnerability was initially mischaracterized in impact assessment, with subsequent revisions correcting the affected products list.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided firmware updates for affected Siemens SCALANCE and RUGGEDCOM products when available
- Implement network segmentation for industrial control systems per CISA recommended practices
- Monitor for anomalous network behavior on affected devices
- Review and apply defense-in-depth strategies for ICS environments
- Verify current SINEC OS version and upgrade to supported release (3.1 or later)
Evidence notes
The vulnerability description indicates a kernel-level netfilter/nf_tables issue resolved by unregistering flowtable hooks on network namespace exit. Siemens ProductCERT advisory SSA-613116 (referenced via CISA CSAF ICSA-25-226-15) identifies affected products including RUGGEDCOM RST2428P and SCALANCE X-family switches. The advisory was initially published 2025-08-12 and most recently updated 2026-02-25 to reflect corrections to affected products list and removal of rejected CVEs. No CVSS score is provided in the source material.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-48935 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-48935
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-48935 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-48935
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-226-15.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-613116.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-613116.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-226-15
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.